Video | Tableau | Tool strategy | Analytics

Tableau Tutorial for Beginners: Tableau Server & Tableau Online Permissions: Part 1

Tableau Server permissions are the most requested topic on my channel, so let's level the playing field and learn exactly how Tableau decides who can see what.

Part ofTableau Server
Watch on YouTube
  • Roles set the foundation for permissions, ranging from server admin and site admin down through project owners, content owners, explorers and viewers, with each tier having a defined scope of access.
  • Permissions can be applied either when publishing content or by placing content in a folder so it inherits that project's permissions, and you can lock permissions to a project to propagate them down to all content and nested projects.
  • Tableau evaluates effective permissions in a strict order: capability outside role, admin/project leader, content owner, then denied/allowed at user level before group level, with no permissions defaulting to denied.
  • Because Tableau checks denial first in the flow, hitting deny for all users blocks everyone even if you later grant a group access; using the 'none' template instead is safer since the default outcome is still denied.
  • Each content type (projects, workbooks, data sources, flows, metrics) exposes a different permissions matrix, and the 'set permissions' or 'administer' capability is dangerous as it lets users change their own access.

This video sets out how Tableau Server and Tableau Online decide who can see and do what, covering the role hierarchy and the exact order Tableau checks permissions in — knowledge you need before you can confidently manage access or troubleshoot why someone can or can't see something.

Aimed at anyone administering or publishing to Tableau Server/Online who needs to control access at scale rather than manage it person by person. Uses a sample site with projects, nested folders and content (workbooks, data sources, metrics) to illustrate the permissions interface.

The Breakdown
  • Roles set the ceiling for access 2:00

    Access runs from server admin (full control) down through site admin, project owner, content owner, then explorer or viewer, with each tier having a defined scope. Explorers get slightly more than viewers, such as the ability to download detail behind summary data.

  • Projects can be nested, content sits inside them 3:33

    A project is just a folder, and folders can contain folders, making nested projects. Content owners are the people who publish workbooks, flows or data sources into these projects, and publishing effectively makes them the owner of that content.

  • Apply permissions at publish or via folder placement 6:48

    You can set permissions either when content is published or by placing content into a project so it inherits that project's settings. The permissions window changes its options depending on whether you're looking at a project, workbook, data source, flow or metric, since each content type exposes a different matrix.

  • Lock permissions to a project to propagate them 8:51

    Locking a project's permissions pushes them down to all content and nested projects within it, which avoids an author accidentally granting the wrong access on publish. This is one option, not mandatory — leaving it unlocked lets individual content owners retain more control over their own items.

  • Use the test permissions panel to check real access 12:08

    Before assuming your settings work, type a user's name into the test area to see their effective access. This is especially useful on complex projects where permissions look correct at a glance but don't behave as expected.

  • Tableau evaluates permissions in a fixed order 13:38

    The flow always checks, in sequence: is this outside your role's capability; are you an admin or project leader; are you the content owner; have you been denied as a user; have you been allowed as a user; are you denied as a group; are you allowed as a group; and if nothing matches, access defaults to denied. This order matters because denial is checked before allowance, so a user-level deny always wins over a later group-level allow.

  • Use 'none' rather than 'denied' for safety 17:36

    Setting 'all users' to denied blocks everyone permanently regardless of later group grants, because deny is evaluated first. Using 'none' instead is safer since the default outcome is still deny-by-default if no explicit permission is found, without the risk of an accidental blanket lock-out.

  • Locking to a project changes the evaluation path 20:11

    When permissions are locked to a project, Tableau's fuller evaluation model checks project-level denial/allowance rather than working through individual content or view-level permission rules. If unlocked, it instead checks content-level rules (view, workbook, data source, flow) before falling back to the same user-then-group check — useful to know when troubleshooting why access differs between locked and unlocked projects.

Worth Knowing
  • Denying 'all users' blocks everyone even if you later grant a specific group access, because Tableau checks denial before allowance in the flow — use 'none' instead.
  • The 'set permissions' or 'administer' capability is dangerous: it lets a user change their own permissions, so restrict who gets it.
  • Tableau checks user-level permissions before group-level ones, so you can deny a whole group but still explicitly allow one user within it.
  • If no permission is found anywhere in the chain, the default outcome is always denied, so you don't need to manually lock everything down defensively.
Use It When

Reach for this when you're setting up governance on a new Tableau Server/Online site, or troubleshooting why a user can or can't see specific content and need to trace exactly which rule in the evaluation chain is deciding the outcome.

How this Rollup was made provenance & method

A Rollup is drafted by AI from the video's transcript, then reviewed and edited by Tim. Everything used to produce this one is listed below — the model, the exact prompt, and the source video — so the process is transparent and reproducible.

Transcription
On-device — NVIDIA Parakeet v3 for recent videos, OpenAI Whisper large-v3 for earlier ones. The transcript never leaves the machine or gets published.
Drafting
Claude Sonnet 5 in the cloud, from that transcript.
Prompt
The exact Rollup prompt (v2) — the full system prompt, unedited.
Source video
Watch on YouTube
Drafted
5 July 2026 at 09:38
Reviewed & edited
11 July 2026 at 13:36 · by Tim Ngwena

Model + prompt + video is everything you'd need to recreate a Rollup like this yourself. The one thing we don't share is the transcript.

Rights. The video and its transcript are the property of TN Media Ltd. Unauthorised use or download is prohibited. © TN Media Ltd.